Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-69428 — A critical access control vulnerability in locally deployed Pro-Bit application in versions less than v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories. | Kitploit
Tools/GitHubGitHub/jasetpen/cve-2025-69428
Vulnerability AnalysisInformation GatheringWeb SecurityPenetration TestingMisconfiguration
GitHubjasetpen/cve-2025-69428

CVE-2025-69428

A critical access control vulnerability in locally deployed Pro-Bit application in versions less than v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

View Repository
4 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Security Advisory - CVE-2025-69428

Title: Unauthenticated Access to Sensitive Directory (Information Disclosure)

CVE-ID: CVE-2025-69428

Description

A critical access control vulnerability in locally deployed Pro-Bit application in versions less than v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

The directory was publicly accessible without any authentication or authorization checks. It contained highly sensitive files including:

  • Plaintext user credentials and corresponding domain accounts
  • Database connection strings
  • Internal host information
  • Encryption methods, keys, and encrypted service-user passwords

This information could be used by an attacker to further compromise the system.

Status: Patched by the vendor.

Disclosure Timeline:

  • Reported: 4th Dec 2025
  • Vendor patched: 11th Dec 2025
  • CVE assigned: CVE-2025-69428
Download Tool